Skip to content
Back to skills

Mobilebuildmcp Tool Contract Review

ASecurity

Use when reviewing MobileBuildMCP tool contract changes across implementation, manifests, workflow membership, output schema metadata, and next-step templates.

  • 6,449 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 30, 2026
ai-agentsrails

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 30, 2026

npx -y skills add getsentry/XcodeBuildMCP --skill mobilebuildmcp-tool-contract-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mobilebuildmcp Tool Contract Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mobilebuildmcp Tool Contract Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/getsentry-mobilebuildmcp-tool-contract-review/badge)](https://www.skillsdirectory.com/skills/getsentry-mobilebuildmcp-tool-contract-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mobilebuildmcp-tool-contract-review
description: Use when reviewing MobileBuildMCP tool contract changes across implementation, manifests, workflow membership, output schema metadata, and next-step templates.
---

# MobileBuildMCP Tool Contract Review

Review guardrails for tool contract changes across implementation, manifests, and workflow exposure.

## Review scope

- Review-only by default.
- Do not edit product code unless the user explicitly requests implementation changes.

## Files to inspect

- `src/mcp/tools/**`
- `manifests/tools/*.yaml`
- `manifests/workflows/*.yaml`
- `src/core/manifest/schema.ts`
- `src/runtime/tool-catalog.ts`
- `src/runtime/types.ts`
- `xcodebuildmcp.com/app/docs/_content/tool-authoring.mdx`
- `xcodebuildmcp.com/app/docs/_content/architecture-manifest-visibility.mdx`

## Guardrails

- Manifest `id` matches filename.
- Manifest `module` points to implementation path without extension.
- Tool module exports named `schema` and `handler`.
- `names.mcp` remains globally unique.
- `names.cli` stays workflow-local and consistent with CLI docs/fixtures.
- Tool appears in at least one workflow unless intentionally hidden by availability.
- `outputSchema` is present for tools that set `ctx.structuredOutput`.
- `nextSteps.toolId` references existing manifest tool IDs.
- Avoid parallel legacy paths or duplicate implementation paths.

## Validation

- `npm run typecheck`
- `npm test -- src/core/manifest/__tests__/schema.test.ts`
- `npm test -- src/runtime/__tests__/tool-invoker.test.ts`
- `npx skill-check .agents/skills/mobilebuildmcp-tool-contract-review`

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…